41 System Hardening – SSH Public Key Authentication with Linux
41 System Hardening – SSH Public Key Authentication with Linux
Jacob Christensen; Isha Patel; and Arjun Nath
In the modern day, one of the most common forms of authentication we encounter are Single Sign-On (SSO) passwords. You may recognize this as a password you type to access a store’s website or the credentials you enter to log on to a video game service. While it is the most commonly used form of authentication, it is not the only option. In this chapter, we will be exploring a more secure alternative through asymmetric encryption. Asymmetric encryption utilizes two keys: a public key (which is typically freely available and has no cost to security if exposed) and a private key (which must never be shared under any circumstances). The basic idea is that anything encrypted with one key can only be decrypted with the other. In this chapter, we will be implementing Public Key Authentication to further harden our Linux servers on our network.
Learning Objectives
- Learn how to implement Public Key Authentication for remote server administration
- Learn how to harden SSH against common cyber attacks
Prerequisites
Deliverables
- Screenshot of GNS3 Network
- Screenshot of cat ~/.ssh/authorized_keys command
- Screenshot of a successful connection to ssh with public key authentication
- Screenshot of Ubuntu Desktop being refused connection due to no public key
Resources
Contributors
- Kyle Wheaton, Cybersecurity Student, ERAU-Prescott
- Dante Rocca, Cybersecurity Student, ERAU-Prescott
- Jungsoo Noh, Cybersecurity Student, ERAU-Prescott
Phase I – Building the Network Topology
The following steps are to create a baseline network for completing this chapter. It makes assumptions about learner knowledge from completing previous labs.
By the end of this lab, your network should look like the following:
- Start GNS3
- Create a new project: LAB_24
NOTE: The lab takes heavy influence from the chapter Network Monitoring – Honeypots. It is recommended to save that file as a new project and make adjustments as necessary.
- Create a new project: LAB_24
Phase II – Configuring Public Key Authentication
To begin implementing a Public Key Authentication system, we first need to generate a public key pair. We’ll give the DMZ server with the public key. This key will act as the authenticator of anyone who attempts to log in holding the private key. We give the private key to the Kali machine, and later attempt to launch an SSH session from the Kali machine to the DMZ server
- In the corp[.]local subnet, start the IT laptop (Kali) and login
- Ensure that SSH is enabled and active
> systemctl enable ssh.service
> systemctl restart ssh.service
- Generate a new RSA public/private key pair
> ssh-keygen -t rsa -b 3072
- Press enter when prompted where to save the key to place it in its default location: ~/.ssh/id_rsa
- You may enter a password to further protect your private key, but you can also press enter again twice to skip this
- Verify that the both the private (id_r